MAS PS-G04 Audit Readiness Guide for PSPs (2026)
MAS PS-G04 Audit Readiness: What Singapore Payment Service Providers Need to Prepare For
Introduction
From 16 July 2026, the annual audit that every licensed payment service provider in Singapore already budgets for changes in substance, even if the paperwork looks familiar. The Monetary Authority of Singapore has issued PS-G04, a guideline that pushes external auditors well beyond checking that financial statements are accurate.
Auditors are now expected to test whether your AML/CFT controls, safeguarding arrangements, technology risk framework and regulatory reporting actually work in practice, and whether issues raised in prior years were genuinely closed out. For compliance officers and MLROs, this means the groundwork for a clean audit now starts months earlier than it used to.
This guide walks through what PS-G04 requires, where MAS auditors will focus, and the practical steps Pecuniya recommends taking before your audit window opens.
Executive Summary
- PS-G04 takes effect on 16 July 2026 and applies to all licensed payment service providers under the Payment Services Act.
- MAS now expects the annual audit to test regulatory compliance, risk management and internal controls, not just confirm that filings were made.
- Six areas will receive close scrutiny: AML/CFT controls, safeguarding of customer monies, base capital compliance, technology risk and cyber resilience, accuracy of MAS regulatory reporting, and remediation of prior findings.
- Newly licensed PSPs face an additional end-to-end review of AML/CFT and technology risk controls one year after operations begin.
- Auditors are expected to test operating effectiveness through sample testing and substantive review — documentation that a control exists on paper is no longer enough.
- Early preparation, rather than a scramble in the weeks before the auditor arrives, is what separates a smooth audit cycle from a stressful one.
Why This Regulatory Update Matters
Every licensed PSP is already required to appoint a qualified external auditor each financial year, lodge Form 4 within six months of financial year-end, furnish audited financial statements, submit an Independent Assurance Report, and provide MAS with the auditor’s findings, observations and management letter.
PS-G04 does not remove any of these obligations. What it changes is the depth of what the audit is expected to cover. Rather than treating the audit as a filing exercise, MAS has set out its expectation that the audit itself becomes a mechanism for testing whether a PSP’s compliance and risk management framework functions as intended.
This matters because it shifts the burden onto the PSP well before the auditor’s fieldwork begins. If evidence of a control’s operation cannot be produced quickly and clearly, that gap itself becomes an audit observation — regardless of whether the underlying control is sound.
Who Is Affected
- Licensed payment service providers under the Payment Services Act, across all licence classes.
- Newly licensed PSPs and existing PSPs adding a newly licensed payment service, who face additional first-year review requirements.
- Compliance, risk, internal audit, technology and finance functions that will need to produce evidence on request.
- Boards and senior management, who remain accountable for the effectiveness of the control environment MAS is testing.
Business Implications
- Audit preparation becomes a year-round discipline rather than a pre-audit sprint.
- Documentation and evidence trails need to be maintained continuously, not reconstructed retrospectively.
- Prior audit and inspection findings need a formal tracking mechanism through to verified closure.
- Technology risk and AML/CFT functions should expect more detailed, evidence-based auditor requests than in previous cycles.
Key Regulatory Changes
The table below summarises how the audit expectation shifts under PS-G04 compared with the position PSPs have generally worked to until now.
| Area | Before PS-G04 | Under PS-G04 |
| Audit scope | Confirm financial statements, Form 4 lodgement and Independent Assurance Report are filed | Additionally test regulatory compliance, risk management frameworks and internal control effectiveness |
| Prior findings | Management confirms issues have been addressed | Auditor must verify closure with supporting evidence, not a simple assurance statement |
| Control testing | Largely a design and documentation check | Operating effectiveness tested through sample testing and substantive review |
| New PSPs | No distinct first-year requirement beyond standard audit | End-to-end review of AML/CFT and technology risk controls one year after launch |
| Evidence expectation | Policies and procedures on record | Evidence the control is documented, consistently applied and traceable through a clear audit trail |
Download the complimentary MAS PS-G04 Audit Readiness Guide and prepare your organization for the new regulatory audit expectations.
📘 https://www.pecuniya.com/wp-content/uploads/2026/08/Pecuniya-MAS-PS-G04-Audit-Readiness-Guide.pdf
Note: This comparison reflects Pecuniya’s reading of the PS-G04 Guidelines and is provided as Expert Analysis to aid interpretation. It is not a substitute for the original guideline text.
Detailed Analysis
MAS has indicated that audits should remain risk-based and scaled to each PSP’s size and business model. Even so, every licensed entity should expect close attention to the six areas below.
1. AML/CFT Controls and Financial Crime Risk
Auditors will test the design and operation of your money-laundering and terrorism-financing controls, including:
- Enterprise-wide risk assessments
- Customer due diligence procedures
- Name and sanctions screening
- Transaction monitoring
- Suspicious transaction reporting
- Record-keeping and governance oversight
Expert Analysis: In practice, the enterprise-wide risk assessment is often the weakest link because it is completed once at licensing and rarely refreshed as products, customer segments or geographies change. Treat it as a living document reviewed at least annually.
2. Safeguarding of Customer Monies and Assets
Safeguarding arrangements are a mandatory review area for every PSP. Auditors will confirm that the way relevant monies and customer assets are protected meets the standards set out in the Payment Services Act.
3. Base Capital Compliance
PSPs must be able to demonstrate, on an ongoing basis, that minimum base capital levels and adequate financial resources are being maintained — not only at the point of licensing, but throughout the year.
4. Technology Risk Management and Cyber Resilience
Technology and cyber risk remain a top MAS priority. Auditors are expected to examine:
- Cyber hygiene practices
- Access management controls
- IT resilience and business continuity
- Security operations
- Data and infrastructure security
- Technology governance and software development lifecycle controls
Expert Analysis: Access management is frequently where evidence gaps appear — particularly proof that leaver access was revoked promptly and that privileged access is periodically recertified. Export and retain the relevant logs ahead of the audit window rather than pulling them under time pressure.
5. Accuracy of MAS Regulatory Reporting
Auditors are expected to verify that information submitted to MAS — including relevant PSN04 returns — is both accurate and complete.
6. Remediation of Prior Findings
MAS specifically expects auditors to check whether issues raised in earlier audits or inspections have been properly resolved, with evidence to support closure rather than a simple assurance that the matter has been fixed.
Additional Expectations for Newly Licensed PSPs
PS-G04 introduces extra requirements for newly licensed PSPs, and for existing PSPs adding a newly licensed payment service. One year after operations, or the new service, begin, auditors are expected to carry out an end-to-end review covering AML/CFT controls and technology risk management controls.
These reviews go beyond a design check — auditors are expected to test operating effectiveness through sample testing and substantive review, not simply confirm that a policy exists on paper.
Business Impact
| Impact Area | What Changes |
| Operational | Evidence collection needs to be built into day-to-day processes, not assembled retrospectively before the audit |
| Compliance | AML/CFT and safeguarding frameworks need periodic self-testing, not just annual review |
| Technology | Access logs, resilience testing records and SDLC documentation need to be audit-ready year-round |
| Governance | Committee papers and board oversight records need to clearly evidence challenge and decision-making |
| Financial | Base capital and financial resource adequacy must be demonstrably monitored on an ongoing basis |
| Risk | Prior findings need a formal tracker through to verified, evidenced closure |
| Customer | Stronger safeguarding and AML/CFT evidence reduces the risk of service disruption from a qualified or adverse audit outcome |
Implementation Roadmap
The following roadmap, provided as Expert Analysis, sets out a practical sequence for building PS-G04 readiness ahead of your audit window.
| Timeline | Activities | Owner | Deliverables | Priority |
| Immediate | Map PS-G04’s six focus areas against current controls and identify obvious gaps | Compliance / MLRO | Initial gap register | High |
| 30 Days | Refresh the enterprise-wide AML/CFT risk assessment; consolidate technology risk evidence (access logs, BCP tests) | Compliance, Technology | Updated risk assessment; evidence pack | High |
| 60 Days | Track prior audit and inspection findings to closure with supporting evidence; validate safeguarding arrangements | Internal Audit, Finance | Remediation tracker with evidence | Medium |
| 90 Days | Conduct an internal dry-run audit against PS-G04 expectations; brief the board and senior management | Internal Audit, Board | Readiness report; board pack | Medium |
Audit Readiness Checklist
| Task | Priority | Evidence Required | Owner | Status |
| Refresh enterprise-wide ML/TF risk assessment | High | Signed-off risk assessment document | MLRO | ☐ |
| Verify customer due diligence files are complete | High | Sample of CDD files with audit trail | Compliance | ☐ |
| Confirm sanctions screening logs are retained | High | Screening system logs and alert dispositions | Compliance | ☐ |
| Test transaction monitoring alert handling | High | Alert closure records and escalation notes | Compliance | ☐ |
| Confirm safeguarding arrangements meet PSA standards | High | Bank confirmations, trust or insurance documentation | Finance | ☐ |
| Evidence base capital adequacy through the year | Medium | Monthly capital adequacy calculations | Finance | ☐ |
| Export access management logs (joiners, movers, leavers) | High | Access review and revocation records | Technology | ☐ |
| Validate BCP and cyber resilience testing | Medium | Test results and remediation notes | Technology | ☐ |
| Verify PSN04 returns for accuracy and completeness | High | Reconciled return data and supporting workings | Finance / Compliance | ☐ |
| Track prior findings to evidenced closure | High | Remediation tracker with supporting evidence | Internal Audit | ☐ |
| Assemble governance committee papers | Medium | Minutes evidencing challenge and decisions | Company Secretary | ☐ |
Top 10 Common Mistakes
Based on Pecuniya’s experience supporting MAS-regulated entities through audit cycles, these are the most frequent avoidable issues.
- Treating the risk assessment as a one-off document. It is completed at licensing and never revisited, so it no longer reflects current products or customers. Review it at least annually.
- Assuming a policy is the same as a control. Auditors test whether a control operates in practice, not whether a policy exists. Keep operating evidence, not just documents.
- Losing track of prior findings. Without a formal tracker, findings get informally “fixed” with no evidence of closure. Maintain a single remediation log.
- Inconsistent application across teams. A control that works in one team but not another is a control gap. Standardise procedures and checklists.
- Evidence scattered across systems and inboxes. When evidence cannot be located quickly, it looks like the control does not exist. Centralise audit evidence ahead of time.
- Access management left unreviewed. Leaver access that is not promptly revoked is a recurring technology risk finding. Schedule periodic access recertification.
- Regulatory changes not fully rolled out operationally. Policy updates are made, but front-line procedures and training lag behind. Close the loop with staff training and sign-off.
- Safeguarding evidence prepared only at year-end. Safeguarding needs to be demonstrably continuous, not a snapshot. Retain periodic confirmations throughout the year.
- PSN04 returns reconciled late. Late reconciliation increases the risk of errors surfacing during the audit itself. Reconcile on a rolling basis.
- Board papers that record decisions but not challenge. MAS and auditors look for evidence of effective oversight, not just approval. Minute the questions raised, not only the outcome.
Expert Recommendations
The following recommendations reflect Pecuniya’s professional experience supporting PS-G04 readiness. They are Expert Analysis and industry best practice, not statements of MAS’s regulatory requirements.
- Run an internal dry-run audit 90 days before your external audit window, scoped to the six PS-G04 focus areas.
- Assign a single owner for the remediation tracker so prior findings cannot fall through organisational gaps.
- Build a standing evidence repository, updated monthly, rather than reconstructing evidence under audit pressure.
- Brief the board on PS-G04 expectations early, since governance oversight itself is now part of what is being tested.
- Treat technology access management as a recurring control, with quarterly recertification rather than an annual check.
Frequently Asked Questions
What is MAS PS-G04?
PS-G04 is a MAS guideline that sets out expectations for how the annual external audit of licensed payment service providers should be conducted, effective 16 July 2026.
Who does PS-G04 apply to?
PS-G04 applies to all licensed payment service providers under the Payment Services Act, including newly licensed PSPs and those adding a newly licensed payment service.
Does PS-G04 create new filing obligations?
PS-G04 does not remove existing obligations such as appointing an external auditor, lodging Form 4, and submitting an Independent Assurance Report. It expands what the audit itself is expected to test.
What are the six focus areas under PS-G04?
AML/CFT controls, safeguarding of customer monies and assets, base capital compliance, technology risk management and cyber resilience, accuracy of MAS regulatory reporting, and remediation of prior findings.
What additional requirement applies to newly licensed PSPs?
One year after operations or a newly licensed service begins, auditors are expected to conduct an end-to-end review of AML/CFT controls and technology risk management controls.
What does ‘testing operating effectiveness’ mean?
It means auditors verify a control actually functions as intended, typically through sample testing and substantive review, rather than only confirming a policy document exists.
How should prior audit findings be tracked?
Through a formal remediation tracker that records the finding, the corrective action taken, and evidence supporting closure, rather than a verbal or informal assurance.
What evidence can auditors request under PS-G04?
Examples include business model and customer profile information, products and services offered, licensing conditions, regulatory breaches and supervisory actions, outstanding audit findings, enterprise-wide risk assessments, governance committee papers, and previous gap assessments.
Why do most audit observations occur?
In Pecuniya’s experience, most observations arise from incomplete documentation, evidence that cannot be located quickly, inconsistent application of controls, regulatory changes not fully rolled out, and prior findings that were never formally tracked to closure.
How early should a PSP start preparing for a PS-G04 audit?
Preparation should begin well before the audit window opens, ideally 90 days or more, since assembling documented, traceable evidence takes time.
Does PS-G04 change base capital requirements?
PS-G04 does not change the underlying capital requirements, but it reinforces that PSPs must demonstrate ongoing compliance with them, not just compliance at a single point in time.
What is a PSN04 return?
PSN04 is a regulatory return submitted to MAS by licensed payment service providers; PS-G04 expects auditors to verify its accuracy and completeness.
Can Pecuniya help with PS-G04 readiness?
Yes. Pecuniya offers PS-G04 audit readiness assessments, gap analysis, AML/CFT internal audit, technology risk review, and remediation validation for licensed PSPs.
Conclusion
PS-G04 signals that MAS expects licensed payment service providers to run mature, well-documented and demonstrably effective control environments — not only at audit time, but throughout the year.
The six focus areas set out in this guide give a clear map of where auditors will look first: AML/CFT, safeguarding, base capital, technology risk, regulatory reporting accuracy, and remediation of prior findings. Newly licensed PSPs carry an additional obligation to demonstrate operating effectiveness within their first year.
The PSPs that manage this transition smoothly are the ones that treat evidence collection as a continuous discipline rather than a pre-audit scramble. Getting ahead of that expectation, rather than reacting to it, is what separates a smooth audit cycle from a stressful one.
How Pecuniya Can Help
Pecuniya’s compliance advisory team helps PSPs assess audit readiness, strengthen governance and control frameworks, and address the core PS-G04 focus areas — from AML/CFT and safeguarding arrangements to technology risk, cyber resilience and remediation tracking.
| Service Area | What We Review | Outcome for Your Business |
| Audit Readiness Assessment | PS-G04 expectations mapped against current controls, documentation and evidence trail | A clear, prioritised view of gaps before external auditors arrive |
| Gap Analysis Against PS-G04 | Policies and control frameworks benchmarked against PS-G04, the Payment Services Act, MAS Notices and industry practice | A practical remediation roadmap ranked by risk and regulatory impact |
| AML/CFT Internal Audit | Enterprise-wide ML/TF risk assessments, onboarding, screening, monitoring, reporting and governance | Stronger, better-evidenced AML/CFT control effectiveness |
| Technology Risk Review | Technology governance, cybersecurity, access management, resilience and outsourcing oversight | Clearer visibility over technology and cyber exposure |
| Remediation Validation | Testing of corrective actions and evidence against prior audit or MAS findings | A defensible record of remediation progress for regulators and auditors |
| Ongoing Internal Audit Programme | Risk-based audit planning and continuous assurance throughout the year | Compliance treated as a year-round discipline, not an annual scramble |
With over 20 years of hands-on experience supporting MAS-regulated entities, Pecuniya’s team works alongside licensed PSPs — not just as advisors, but as partners in getting ready for PS-G04. If you would like a clear, prioritized view of where your PSP stands, an Audit Readiness Assessment is a practical place to start.


Leave a Reply